Improper Validation of Specified Quantity in Input in Keycloak - CVE-2026-9801

 

Improper Validation of Specified Quantity in Input in Keycloak - CVE-2026-9801

Published: September 5, 2026


Vulnerability identifier: #VU146994
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-9801
CWE-ID: CWE-1284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper validation of specified quantity in input in the LDAP password policy response handling when processing a password authentication request. A remote privileged user can send a malformed LDAP password policy response to cause a denial of service.

The error terminates the Keycloak Java Virtual Machine and disrupts all realms on the affected node.


Affected software

Keycloak
Red Hat build of Keycloak

How to mitigate CVE-2026-9801

Install security update from vendor's website.

Keycloak - update to 26.6.3
Red Hat build of Keycloak - addressed in versions 26.4.13, 26.6.3

External References

Related Security Bulletins